PT-2025-23233 · Unknown · Tinxy Wifi Lock Controller

Published

2025-05-30

·

Updated

2025-07-22

·

CVE-2025-44612

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tinxy WiFi Lock Controller version v1 RF
Description The issue concerns the transmission of sensitive information in plaintext, including control information and device credentials. This allows attackers to possibly intercept and access sensitive information via a man-in-the-middle attack.
Recommendations For Tinxy WiFi Lock Controller version v1 RF, consider implementing encryption for sensitive data transmission to prevent interception. As a temporary workaround, restrict access to the device's network to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-44612

Affected Products

Tinxy Wifi Lock Controller